- Location
- Warsaw, Poland
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Experience
- 8+ years
- Source
- Workday
Description
WHAT MAKES US, US
Join some of the most innovative thinkers in FinTech as we lead the evolution of financial technology. If you are an innovative, curious, collaborative person who embraces challenges and wants to grow, learn and pursue outcomes with our prestigious financial clients, say Hello to SimCorp!
At its foundation, SimCorp is guided by our values — caring, customer success-driven, collaborative, curious, and courageous. Our people-centered organization focuses on skills development, relationship building, and client success. We take pride in cultivating an environment where all team members can grow, feel heard, valued, and empowered.
If you like what we’re saying, keep reading!
WHY THIS ROLE IS IMPORTANT TO US
Security is fundamental to everything we do at SimCorp. As a Security Engineer, you will be a senior technical contributor within our Platform Security team, helping protect our products, cloud environments, platforms, and operations from evolving cyber threats.
Working across cloud security, application security, detection engineering, incident response, and platform security, you will partner closely with Application, Infrastructure, Architecture, and Product Engineering teams to strengthen our overall security posture. We recognize these are broad domains, and no single individual is expected to be an expert in every area. Instead, we are looking for someone who brings strong expertise in one or more security disciplines and a passion for continuous learning.
This is an opportunity to influence security strategy and execution across a global technology organization. Success in this role means delivering meaningful security improvements, strengthening our ability to detect and respond to threats, and enabling engineering teams to build secure and resilient solutions at scale.
WHAT YOU WILL BE RESPONSIBLE FOR
In your daily work, you will collaborate with teams across Engineering, Platform, Product, Architecture, and Security to:
- Lead security engineering initiatives from planning through implementation, driving improvements across cloud, application, infrastructure, and operational security domains.
- Conduct security assessments, architecture reviews, threat modelling exercises, and risk evaluations, helping engineering teams identify and address security gaps.
- Analyze security challenges across multiple technology domains, identify root causes, and work with platform teams to design and implement sustainable solutions.
- Contribute to the development and tuning of detection capabilities using Microsoft Sentinel, Microsoft Defender, KQL analytics, and related security tooling.
- Support the definition and implementation of logging, monitoring, and event collection standards across the platform.
- Participate in incident response activities, including investigation, containment, recovery, root cause analysis, and post-incident reviews.
- Conduct proactive threat hunting activities across environments and systems within your areas of ownership.
- Develop and improve incident response playbooks, security runbooks, and operational security processes.
- Translate threat intelligence, incident findings, and emerging risks into tangible improvements to security controls, monitoring capabilities, and engineering practices.
- Identify security risks proactively and define mitigation strategies before issues can impact the business.
- Lead or contribute to secure software development lifecycle initiatives, security taskforces, architecture discussions, and cross-functional security programs.
- Collaborate with engineering teams to embed security into CI/CD pipelines, development workflows, infrastructure platforms, and cloud architectures.
- Serve as a trusted security advisor for engineers, architects, and product teams, helping guide secure decision-making.
- Communicate technical risks, security recommendations, and incident findings effectively to both technical and non-technical stakeholders, including senior leadership.
WHAT WE VALUE
Most importantly, you can see yourself contributing and thriving in the position described above. How you gained the skills needed for doing that is less important. We expect you to be good at several of the following and be able to - and interested in - learning the rest:
- 8+ years of experience in security engineering, cloud security, application security, cyber defense, incident response, or related fields.
- Experience working within modern cloud environments, ideally including Microsoft Azure.
- Knowledge of cloud security technologies such as Microsoft Defender, Microsoft Sentinel, Entra ID, security monitoring tools, and related services.
- Familiarity with Identity and Access Management concepts and security best practices.
- Understanding of application security principles, including threat modelling, secure development practices, SAST, DAST, and software composition analysis.
- Experience with detection engineering, SIEM technologies, threat hunting activities, and operational security monitoring.
- Knowledge of incident response processes, investigation techniques, and recovery activities.
- Experience with vulnerability management, infrastructure hardening, and security risk mitigation practices.
- Familiarity with Infrastructure as Code technologies such as Terraform or Bicep.
- Experience working with cloud-native technologies, containers, Kubernetes, or similar modern platform architectures.
- Understanding of DevSecOps principles and integrating security into software delivery pipelines.
- Knowledge of security frameworks, attack methodologies, and adversary techniques such as MITRE ATT&CK.
- Ability to work across multiple stakeholder groups and influence positive security outcomes through collaboration and technical expertise.
- Curiosity and motivation to continuously learn, develop, and adapt to an evolving security landscape.
Relevant certifications are welcomed, including Microsoft Security Engineer Associate, Security Operations Analyst, Cybersecurity Architect Expert, or similar industry-recognized certifications.
BENEFITS
- Flexible working hours and hybrid model - 2 days in the office, 3 days remote
- Modern office (next to Wilanowska metro station) with quiet zones and ergonomic workstations
- Base salary with annual bonus structure
- Holiday allowance upon a 2-week vacation
- Occasional remote work across Poland and international options available (up to 24 days domestic, 20 days international per year - subject to internal policy)
- Employer-paid Medicover Platinum healthcare package (employee-paid family upgrade available)
- MyBenefit Cafeteria with a monthly budget provided by SimCorp, which can be used to finance a Multisport card (with a 25% employee contribution) or choose other lifestyle options
- Unum group life insurance (employee-paid upgrade available)
- Medicover travel insurance for private trips and global business travel insurance
- Possibility to join Deutsche Börse Group Share Plan (eligible after 1 year)
- Copyrights program for certain roles
- Possibility to develop your career in an international environment
- Professional training and courses provided by SimCorp
- Polish language classes for foreign employees; German and English classes based on business needs
- Integration events, volunteering initiatives and employee-led clubs
Compensation ranges are being disclosed at the initial stage of candidate engagement.
Visit our career pages to learn more about working at SimCorp: www.simcorp.com/career
NEXT STEPS
Please send us your application in English via our career site as soon as possible, we process incoming applications continually. Please note that only applications sent through our system will be processed. At SimCorp, we recognize that bias can unintentionally occur in the recruitment process. To uphold fairness and equal opportunities for all applicants, we kindly ask you to exclude personal data such as photo, age, or any non-professional information from your application. Thank you for aiding us in our endeavor to mitigate biases in our recruitment process.
WHO WE ARE
For over 50 years, we have worked closely with investment and asset managers to become the world’s leading provider of integrated investment management solutions. We are 3,000+ colleagues with a broad range of nationalities, educations, professional experiences, ages, and backgrounds. SimCorp is an independent subsidiary of the Deutsche Börse Group. Following the recent merger with Axioma, we leverage the combined strength of our brands to provide an industry-leading, full, front-to-back offering for our clients.
SimCorp is an equal-opportunity employer. We are committed to building a culture where diverse perspectives and expertise are integrated into our everyday work. We believe in the continual growth and development of our employees, so that we can provide best-in-class solutions to our clients.
#Li-Hybrid